Privacy-first business dashboard (pre-alpha): connectors encrypt on your device, the hub stores only ciphertext it cannot read. AGPL-3.0-only.
Find a file
Seglamater Support f169bd1523 showcase: republish the curated tree from source commit 2057879f05f6
The tree is exactly the files the declaration ships at that commit, byte for
byte. 23 added, 41 modified, 13 deleted, asserted against the previous tip f289083eeb4d471d4e5542873d334446377f3e1f.
Bytes published before this commit keep the terms they were published under;
this republish corrects the current public copy only.

- modified .gitignore
- added Cargo.lock
- modified Cargo.toml
- modified README.md
- added apps/vantage-connector-chatalot/Cargo.toml
- added apps/vantage-connector-chatalot/src/api.rs
- added apps/vantage-connector-chatalot/src/error.rs
- added apps/vantage-connector-chatalot/src/lib.rs
- added apps/vantage-connector-chatalot/src/main.rs
- added apps/vantage-connector-chatalot/src/mapping.rs
- added apps/vantage-connector-chatalot/tests/end_to_end.rs
- modified apps/vantage-connector-google/Cargo.toml
- modified apps/vantage-connector-google/src/main.rs
- modified apps/vantage-connector-plane/Cargo.toml
- modified apps/vantage-connector-plane/README.md
- modified apps/vantage-connector-plane/src/api.rs
- modified apps/vantage-connector-plane/src/main.rs
- modified apps/vantage-connector-plane/src/mapping.rs
- added apps/vantage-connector-postgres/Cargo.toml
- added apps/vantage-connector-postgres/src/lib.rs
- added apps/vantage-connector-postgres/src/main.rs
- added apps/vantage-connector-postgres/tests/live_postgres.rs
- modified apps/vantage-connector-sdk/Cargo.toml
- added apps/vantage-connector-sdk/build.rs
- added apps/vantage-connector-sdk/src/bootstrap.rs
- added apps/vantage-connector-sdk/src/keyload.rs
- modified apps/vantage-connector-sdk/src/lib.rs
- added apps/vantage-connector-sdk/src/registry.rs
- modified apps/vantage-connector-sdk/src/runner.rs
- modified apps/vantage-connector-stripe/Cargo.toml
- modified apps/vantage-connector-stripe/README.md
- modified apps/vantage-connector-stripe/src/main.rs
- modified apps/vantage-connector-stripe/tests/end_to_end.rs
- modified apps/vantage-connector-wave/Cargo.toml
- modified apps/vantage-connector-wave/src/main.rs
- modified apps/vantage-hub/README.md
- modified apps/vantage-hub/app/api/__init__.py
- modified apps/vantage-hub/app/api/blobs.py
- modified apps/vantage-hub/app/api/health.py
- added apps/vantage-hub/app/api/keymaterial.py
- modified apps/vantage-hub/app/middleware/csp.py
- modified apps/vantage-hub/app/middleware/rate_limit.py
- modified apps/vantage-hub/app/models/user.py
- modified apps/vantage-hub/app/services/storage.py
- added apps/vantage-hub/migrations/versions/005_user_keymaterial.py
- modified apps/vantage-hub/pyproject.toml
- modified apps/vantage-hub/tests/test_blobs.py
- modified apps/vantage-hub/tests/test_health.py
- added apps/vantage-hub/tests/test_keymaterial.py
- added apps/vantage-hub/uv.lock
- modified apps/vantage-keys/Cargo.toml
- modified apps/vantage-keys/src/derive.rs
- modified apps/vantage-keys/src/encrypt.rs
- modified apps/vantage-keys/src/error.rs
- modified apps/vantage-keys/src/lib.rs
- modified apps/vantage-keys/src/master.rs
- modified apps/vantage-keys/src/mkwrap.rs
- deleted apps/vantage-marketing/DESIGN.md
- deleted apps/vantage-marketing/download.html
- deleted apps/vantage-marketing/favicon.svg
- deleted apps/vantage-marketing/index.html
- deleted apps/vantage-marketing/security.html
- deleted apps/vantage-marketing/styles.css
- modified docs/ARCHITECTURE.md
- modified docs/BRAND.md
- deleted docs/customer/README.md
- deleted docs/customer/connectors/google-workspace.md
- deleted docs/customer/connectors/plane.md
- deleted docs/customer/connectors/stripe.md
- deleted docs/customer/connectors/wave-quickbooks.md
- deleted docs/customer/getting-started.md
- deleted docs/customer/privacy.md
- modified vendor/substrate-connector/Cargo.toml
- added vendor/substrate-connector/NOTICE
- added vendor/substrate-connector/PROVENANCE.json
- added vendor/substrate-connector/README.md
- modified vendor/substrate-connector/src/lib.rs
2026-09-23 09:39:01 -06:00
apps showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
docs showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
vendor/substrate-connector showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
.gitignore showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
Cargo.lock showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
Cargo.toml showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
LICENSE showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00
README.md showcase: republish the curated tree from source commit 2057879f05f6 2026-09-23 09:39:01 -06:00

Vantage

Privacy-first business dashboard. Get vantage on your shop, your business, your life — across the services you already use, with the data staying on your hardware.

Vantage by Seglamater Services LLC.

Status

Pre-alpha. The architecture, contracts, and first connectors are landing now. See docs/ARCHITECTURE.md for the design and Plane → VANTAGE for the roadmap.

The privacy story

Vantage encrypts your business data client-side. Connectors pull from the services you already use (Stripe, Google Workspace, Wave, Plane), encrypt each record on your own device with keys derived from your passphrase, and hand the hub only opaque ciphertext. The hub stores and quota-meters blobs it can never read. See docs/ARCHITECTURE.md for the full design and docs/BRAND.md for the positioning and the claims-discipline that keeps the privacy guarantee truthful.

Repository layout

vantage/
├── apps/
│   ├── vantage-hub/              # FastAPI backend — encrypted blob storage
│   ├── vantage-keys/             # Rust crate — client-side cryptography
│   ├── vantage-connector-sdk/    # Rust crate — connector framework
│   ├── vantage-connector-stripe/ # Stripe data feed
│   ├── vantage-connector-google/ # Gmail + Calendar data feed
│   ├── vantage-connector-wave/   # Wave accounting data feed
│   ├── vantage-connector-plane/  # Plane tickets data feed
│   ├── vantage-desktop/          # Tauri 2 dashboard app
│   ├── vantage-cockpit/          # Internal operator cockpit (server-reads, NOT E2EE)
│   └── vantage-marketing/        # getvantage.app static site
├── docs/                         # ARCHITECTURE.md, BRAND.md, etc.
├── vendor/
│   └── substrate-connector/      # Hash-pinned snapshot of the shared Connector primitive
└── scripts/                      # Vendored-crate drift checker + leak scan

vantage-cockpit is the internal operator cockpit, not the customer product. It reads on the server and is not end-to-end encrypted. Do not treat it as a template for customer-facing work.

Quick start (developers)

Requires Rust 1.75+, Python 3.11+, and Node with pnpm. Everything below runs from a fresh clone with no sibling checkouts and no network fetch of internal crates.

# Rust workspace — connector SDK, connectors, crypto crate
cargo build --workspace
cargo test --workspace

# Hub backend (FastAPI)
cd apps/vantage-hub
python3 -m venv .venv && .venv/bin/pip install -e ".[dev]"
.venv/bin/pytest

# Desktop dashboard (Tauri 2 + SvelteKit)
cd apps/vantage-desktop
pnpm install
pnpm test
pnpm build

On pnpm 10 and later, pnpm install installs everything but then exits non-zero with ERR_PNPM_IGNORED_BUILDS because esbuild has an unapproved build script. Run pnpm approve-builds once to clear it, or invoke the tools directly (./node_modules/.bin/vitest run, ./node_modules/.bin/vite build). The lockfile predates that policy; re-locking under current pnpm is tracked separately.

Verify the vendored shared crate has not drifted from its pinned upstream:

python3 scripts/check-vendor-substrate-connector.py check
python3 scripts/check-vendor-leakscan.py

Both exit non-zero on drift. vendor/substrate-connector/ is a distribution artifact, never a fork — edit the crate upstream and re-vendor through the reviewed procedure in docs/ARCHITECTURE.md.

License

AGPL-3.0-only, the license for all Seglamater products. See the LICENSE file at the repository root.

AGPL rather than GPL is deliberate: it closes the network-use gap. A party running a modified copy as a hosted service must publish their source — which is exactly the exposure for a self-hosted product someone could otherwise run as a competing SaaS. GPL-3.0 does not cover that case.

Declared once in [workspace.package]; every member crate inherits it via license.workspace = true, and vantage-hub and vantage-cockpit declare it in their pyproject.toml. vendor/substrate-connector remains independently MIT — vendoring it here does not relicense it, and MIT is compatible with an AGPL-3.0-only work.